Package
openstack-nova-2025.2
Component
oslo-messaging
Latest update
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable component is the Python package oslo-messaging (OpenStack oslo.messaging). Per the GitHub Security Advisory at https://github.com/advisories/GHSA-76qh-xr7q-h39m, there is no patched version for oslo-messaging (vulnerable range >=1.0.0,<=17.3.0). Upstream OpenStack oslo.messaging maintainers will need to release a fixed version of oslo-messaging in order to resolve this CVE.
Status